Summary
The remote host is missing an update to gforge
announced via advisory DSA 1094-1.
Joxean Koret discovered several cross-site scripting vulnerabilities in Gforge, an online collaboration suite for software development, which allow injection of web script code.
The old stable distribution (woody) does not contain gforge packages.
Solution
For the stable distribution (sarge) this problem has been fixed in version 3.1-31sarge1.
For the unstable distribution (sid) this problem has been fixed in version 3.1-31sarge1.
We recommend that you upgrade your gforge package.
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201094-1
Severity
Classification
-
CVE CVE-2005-2430 -
CVSS Base Score: 4.3
AV:N/AC:M/Au:N/C:N/I:P/A:N
Related Vulnerabilities